Amazon doesn't have access to the data on the instance, or a list of processes running inside of it, or similar.
Amazon doesn't have access to the data on the instance, or a list of processes running inside of it, or similar.
The CPU or GPU pattern of bitcoin mining must be completely unambiguous and trivial for Amazon to detect on EC2 instances. Or am I wrong for some reason?
For instance if you look for a magic number. Instead of putting two numbers on the stack, and perform an addition you now have to have a conditional jump before the addition.
Maybe I'm wrong, but at least I think it would be virtually impossible.
If they want to be neutral and not do introspection like this without permission, they can ask the user on sign-up if they want "Protection from mining processes" where sudden activity spikes will cause them to do introspection and shut down an instance if it seems to be bitcoin mining.
EDIT: plus, bitcoin mining is the same operation over, and over, and over, and over again. You don't have to "catch" it doing a particular operation. A brief sample taken at any time will show the VM doing the same exact thing. (tons of SHA hashes.)
I'm not an expert though so perhaps I'm missing something!